Question 1 of 30
A global e-commerce firm is migrating its customer database to a Software-as-a-Service (SaaS) platform provided by an external vendor. The firm\'s legal department has raised concerns about ensuring the continued confidentiality and integrity of sensitive customer Personally Identifiable Information (PII) as mandated by regulations like GDPR. Which ISO/IEC 27002:2013 control, when properly implemented through contractual agreements and ongoing oversight, most directly addresses the security implications of this outsourcing arrangement?
Establishing comprehensive supplier agreements that explicitly define information security requirements and responsibilities for data protection and incident management.
Implementing robust physical security measures at the organization's primary data center to safeguard against unauthorized access to legacy systems.
Developing a detailed business continuity plan that outlines procedures for recovering critical IT services in the event of a major disaster affecting the organization's internal infrastructure.
Conducting regular vulnerability assessments and penetration testing on the organization's internal network to identify and remediate security weaknesses.

Preparing for ISO/IEC 27002:2013 Code of Practice for Information Security Controls Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free